TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel
-
Updated
Mar 25, 2026 - HCL
TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel
Complete Azure Monitor implementation for VM observability with Terraform. Features Log Analytics workspace, VM Insights via Azure Policy, custom KQL alerts (CPU>95%, Memory>90%), metric alerts, interactive dashboards with 6 components, and custom workbooks. Includes email notifications and RBAC configuration.
Terraform-managed Azure infra with Azure Monitor observability and GitHub Actions CI/CD (OIDC) + KQL queries
Azure Zero Trust lab using Terraform, Defender for Cloud, and Microsoft Sentinel to deploy a monitored Windows VM, collect security telemetry, and detect brute-force activity with MITRE-aligned analytics.
Enterprise Azure operational templates and documentation
Complete Application Insights monitoring for ASP.NET web app with Azure DevOps CI/CD integration. Features automated deployment pipelines, availability testing, custom KQL alerts for 5xx errors and failed requests, CPU/Memory alerts, dashboard with 10+ metrics (response time, users, top URLs), and interactive workbooks.
Production-style Azure Secure Landing Zone built with Terraform. Implements hub-and-spoke architecture, NSG security controls, jump host access pattern and centralized monitoring with Log Analytics and KQL. Built under Azure Student subscription constraints.
Azure Governance - bits & pieces
Complete AKS monitoring with Container Insights using Terraform. Multi-platform cluster with Linux/Windows node pools, Prometheus metrics integration, pod-level alerting, and comprehensive visualizations. Features custom KQL alerts for pod failures, dashboard with 8 cluster metrics, and interactive workbooks for analysis.
Add a description, image, and links to the kql topic page so that developers can more easily learn about it.
To associate your repository with the kql topic, visit your repo's landing page and select "manage topics."